Peripheral Device Denial-of-Service Protection via Early Challenge

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Denial-of-service attacks in communication systems, particularly in wireless communication, can drain the limited energy of devices like those powered by batteries, as rogue devices repeatedly attempt to set up communication, leading to excessive energy consumption and processing time.

Innovation Solution

Implementing an early challenge mechanism in the communication setup process between central and peripheral devices, where the peripheral device provides a cryptographic challenge in its advertising address, allowing for early detection and termination of untrusted central devices, reducing the number of messages exchanged and thus conserving energy and processing time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a peripheral device performs complete communication setup procedures with central devices, then communication reliability is improved, but energy consumption and processing time increase significantly

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The peripheral device performs preliminary cryptographic verification of the central device's identity and trustworthiness before initiating full communication setup procedures. This early challenge-response mechanism filters out rogue devices before they can consume energy on complete communication protocols.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements an early termination mechanism that allows the peripheral device to skip the remaining communication setup steps when a rogue device is detected during the challenge-response phase. This rushes through the verification process by immediately terminating connections with untrusted central devices, saving energy on unnecessary protocol execution.

Inventive Principle:
Principle #21Skipping (Rushing through)

2Adaptability or versatility

If a peripheral device repeatedly attempts to set up communication with rogue central devices, then communication coverage is improved, but energy consumption increases

Engineering Contradiction:
Improvecommunication coverageVSAvoidenergy consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The peripheral device uses feedback from the challenge-response mechanism to determine whether to proceed with full communication setup or terminate the connection. This feedback loop prevents repeated energy-consuming communication attempts with rogue devices while maintaining the ability to communicate with legitimate central devices.

Inventive Principle:
Principle #23Feedback

3Reliability

If address selection is used to prevent rogue devices, then communication security is improved, but adaptability decreases because rogue devices can change addresses

Engineering Contradiction:
Improvecommunication securityVSAvoidaddress flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary cryptographic verification before address-based filtering. The peripheral device sends a challenge to the central device and verifies the response before allowing communication, providing security that is not dependent on address stability and cannot be circumvented by address changes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9923713B2Denial-of-service attack protection for a communication device
Publication Date: 2018.03.20 NXP USA INC
  • US9923713B2 patent drawing
  • US9923713B2 patent drawing
  • US9923713B2 patent drawing

AI summary

A peripheral and central device in a wireless network, such as a Bluetooth Low Energy network, may maintain privacy while connecting. During connecting energy in the peripheral device may be saved by linking an advertised address of the peripheral device to a resolvable private address of the central device, thereby providing an early indication if the central device is, according to the peripheral device, allowed to connect to the peripheral device. Hence a peripheral device performing such linking may have an improved resistance to a denial-of-service attack.